Skip to content
PlatformAutomationsPayouts & SubsMobilePricingCompare
Log inGet started
PlatformAutomationsPayouts & SubsMobilePricingCompare
Legal · DPA

Data Processing Addendum

Effective July 24, 2026Last updated July 24, 2026OneRoof CRM

How OneRoof processes Personal Data on the Customer's behalf — service-provider obligations, sub-processors, security incidents, and the technical safeguards behind the platform.

On this page

1 · Introduction2 · Definitions3 · Roles & Scope4 · Processor Obligations5 · Sub-Processors6 · Security Incidents7 · Audits & Records8 · International Transfers9 · Return & Deletion10 · Liability; MiscellaneousAnnex I · Details of ProcessingAnnex II · Security MeasuresAnnex III · Sub-Processors

1Introduction

This DPA forms part of, and is subject to, the Terms of Service between OneRoof Labs LLC ("OneRoof," "Processor," or "Service Provider") and the customer agreeing to the Terms ("Customer," "Controller," or "Business") (each a "Party," together the "Parties"). This DPA governs the Processing of Personal Data by OneRoof on behalf of Customer in connection with the Services. In the event of a conflict between this DPA and the Terms of Service regarding the Processing of Personal Data, this DPA controls.

By accepting the Terms of Service, or by executing this DPA, Customer enters into this DPA on behalf of itself and, to the extent required, in the name and on behalf of its Authorized Affiliates. "Authorized Affiliate" means an entity that controls, is controlled by, or is under common control with Customer, that is permitted to use the Services under the Terms. Customer represents that it is authorized to bind its Authorized Affiliates. All Authorized Affiliates' rights and obligations under this DPA are exercised through Customer, which remains solely responsible for compliance and is the sole party entitled to bring claims under this DPA; the liability limitations in Section 10 apply in the aggregate across Customer and all Authorized Affiliates.

2Definitions

2.1 "Applicable Data Protection Laws" means all privacy and data-protection laws applicable to the Processing of Personal Data under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Colorado Privacy Act ("CPA"), and comparable U.S. state laws.

2.2 "Personal Data" means information relating to an identified or identifiable natural person that is contained in Customer Data and Processed by OneRoof on behalf of Customer under the Terms.

2.3 "Sensitive Data" means Personal Data revealing categories afforded heightened protection under Applicable Data Protection Laws, including Social Security numbers, financial-account information, consumer-screening information, and precise geolocation.

2.4 "Data Subject" means the individual to whom Personal Data relates, including Customer's Consumers and Authorized Users.

2.5 "Processing" (and "Process") means any operation performed on Personal Data, such as collection, recording, storage, use, disclosure, or deletion.

2.6 "Sub-Processor" means a third party engaged by OneRoof to Process Personal Data on its behalf in connection with the Services.

2.7 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by OneRoof. A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as pings, port scans, denied log-in attempts, or other unsuccessful access attempts.

2.9 "Deidentified Data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, and that is processed in compliance with Section 9.2.

2.8 Terms such as "Business," "Service Provider," "Sell," "Share," "Controller," and "Processor" have the meanings given under Applicable Data Protection Laws. Capitalized terms not defined here have the meaning given in the Terms of Service.

3Roles and Scope of Processing

3.1 Roles. With respect to Personal Data, Customer is the Business/Controller and OneRoof is the Service Provider/Processor. Customer determines the purposes and means of Processing; OneRoof Processes Personal Data only as a Service Provider/Processor on Customer's behalf.

3.2 Customer instructions. OneRoof will Process Personal Data only (a) to provide, secure, support, and improve the Services in accordance with the Terms; (b) as further documented in Customer's use and configuration of the Services; and (c) as otherwise instructed in writing by Customer, provided such instructions are consistent with the Terms and lawful. OneRoof will notify Customer if it believes an instruction violates Applicable Data Protection Laws (without obligation to provide legal advice).

3.3 Details of Processing. The subject matter, duration, nature and purpose of Processing, categories of Data Subjects, and types of Personal Data are described in Annex I.

3.4 Customer responsibilities. Customer is responsible for the accuracy and legality of Personal Data and the means by which it acquired it; for providing all required notices to and obtaining all required consents from Data Subjects; for establishing a lawful basis for Processing; and for its own compliance with Applicable Data Protection Laws, including with respect to telephony/recording, skip-traced data, and Sensitive Data as described in the Terms.

4Service-Provider / Processor Obligations

OneRoof will:

4.1 Purpose limitation. Process Personal Data only for the limited and specified purpose of performing the Services for Customer, and not Sell or Share Personal Data, nor retain, use, or disclose Personal Data (a) for any purpose other than the business purposes specified in the Terms and this DPA, including not for any "commercial purpose" other than providing the Services; (b) outside the direct business relationship between the Parties; or (c) by combining Personal Data with personal information received from, or on behalf of, any third party, or collected from OneRoof's own interactions with the Data Subject, except as permitted by Applicable Data Protection Laws to perform the Services.

4.2 Certification. Certify that it understands the restrictions in Section 4.1 and will comply with them.

4.3 Confidentiality. Ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and Process Personal Data only as necessary to perform the Services.

4.4 Security. Implement and maintain the technical and organizational measures set out in Annex II, designed to provide a level of security appropriate to the risk.

4.5 Assistance with Data-Subject requests. Taking into account the nature of the Processing, provide reasonable assistance (including by appropriate technical and organizational measures and self-service tooling within the Services, insofar as possible) to enable Customer to respond to Data Subjects' requests to exercise their rights (such as access, correction, deletion, portability, and opt-out) under Applicable Data Protection Laws, and to fulfill such requests on Customer's documented instruction. If OneRoof receives a request directly from a Data Subject, it will, where permitted, forward the request to Customer without undue delay (and in any event within ten (10) business days), direct the Data Subject to Customer, and will not otherwise respond except on Customer's documented instructions or as required by law.

4.5.1 Sensitive Personal Information. OneRoof will Process Sensitive Data only as necessary to perform the Services and for the purposes permitted under Applicable Data Protection Laws (including, under the CCPA/CPRA, the purposes set out at Cal. Civ. Code § 1798.121 and its regulations), and will not use Sensitive Data to infer characteristics about a Data Subject.

4.6 Assistance with compliance. Provide reasonable assistance to Customer with data-protection impact assessments and consultations with regulators, and with Security-Incident obligations, in each case taking into account the nature of Processing and information available to OneRoof.

4.7 Notice of inability to comply. Notify Customer if OneRoof determines it can no longer meet its obligations under Applicable Data Protection Laws, in which case Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.

4.8 Right to take action. Customer has the right, upon notice, to take reasonable and appropriate steps to help ensure that OneRoof uses Personal Data in a manner consistent with Customer's obligations under Applicable Data Protection Laws, and to stop and remediate unauthorized use of Personal Data.

5Sub-Processors

5.1 General authorization. Customer provides a general authorization for OneRoof to engage Sub-Processors to Process Personal Data, subject to this Section. The current Sub-Processors are listed in Annex III and/or at onerooflabs.com/subprocessors.

5.2 Sub-Processor terms. OneRoof will engage each Sub-Processor under a written contract imposing data-protection obligations that are the same as, or no less protective than, those in this DPA, to the extent applicable to the services the Sub-Processor provides, including engaging each Sub-Processor as a service provider/processor. OneRoof remains responsible for each Sub-Processor's performance of its data-protection obligations and will require each Sub-Processor to delete or return Personal Data on termination.

5.3 Changes. OneRoof will provide advance notice (by email to the Customer's account administrator and/or by a subscribable update to the Sub-Processor list) before adding or replacing a Sub-Processor that Processes Personal Data. Customer may object on reasonable, data-protection-related grounds within 30 days of notice. If the Parties cannot resolve the objection, Customer may, as its sole remedy, terminate the affected Services and receive a pro-rata refund of any prepaid fees for the terminated component covering the period after termination.

6Security Incidents

6.1 OneRoof will notify Customer without undue delay, and in any event no later than seventy-two (72) hours, after confirming a Security Incident affecting Customer's Personal Data. Notice will be provided to the security or administrative contact designated by Customer in the Services (or, absent one, the Customer's account administrator).

6.2 The notification will include, to the extent then known and available to OneRoof, the nature of the incident, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address it. OneRoof will provide reasonable cooperation and updates as more information becomes available.

6.3 As between the Parties, Customer is responsible for determining whether the Security Incident triggers notification obligations to Data Subjects, regulators, or others, and for making any such notifications. OneRoof's notification is not an acknowledgment of fault or liability.

7Audits and Records

7.1 OneRoof will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by providing then-current third-party certifications, attestations, audit reports, or a completed security questionnaire, where available.

7.2 Where Applicable Data Protection Laws require a more direct audit right, Customer (or a mutually agreed independent auditor bound by confidentiality) may, no more than once per twelve (12) months and on at least thirty (30) days' prior written notice, conduct an audit limited to OneRoof's Processing of Customer's Personal Data, during business hours, in a manner that does not disrupt OneRoof's operations or compromise the security or confidentiality of other customers' data. The once-per-twelve-months and notice limitations do not apply following a Security Incident affecting Customer's Personal Data or where a more frequent audit or inspection is required by Applicable Data Protection Laws or a regulator. Each Party bears its own audit costs.

8International Transfers

The Services are operated in the United States, and Personal Data is Processed in the United States. The Parties do not contemplate the transfer of Personal Data subject to EU/UK/Swiss data-protection law under this DPA. If such transfers occur, the Parties will enter into appropriate transfer mechanisms (such as the EU Standard Contractual Clauses and any required UK Addendum), which will be incorporated by reference.

9Return and Deletion

9.1 Return/deletion on termination. Upon termination or expiration of the Services, at Customer's election and written request, OneRoof will delete or return Personal Data Processed on Customer's behalf in accordance with the Terms, and will delete existing copies and instruct its Sub-Processors to do the same, except to the extent retention is required by law, held in routine backups pending deletion in the ordinary course, or maintained as Deidentified Data in accordance with Section 9.2. Personal Data retained in backups remains subject to this DPA's confidentiality and security obligations until deleted. OneRoof's standard retention behaviors (including the automated 90-day purge of stored email message bodies and attachments, hard deletion with referential cascade, and the indefinite persistence of audit and billing records) are described in the Privacy Policy and Annex I/Annex II.

9.2 Deidentification covenant. Where OneRoof retains or uses Deidentified Data, OneRoof will: (a) take reasonable measures to ensure the data cannot be associated with an individual; (b) publicly commit to maintain and use the data only in deidentified form and not to attempt to re-identify it, except to test deidentification; and (c) contractually obligate any recipient of the data to comply with the same restrictions.

10Liability; Miscellaneous

10.1 Each Party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in the Terms to a Party's liability means the aggregate liability of that Party under the Terms and this DPA combined.

10.2 Except as amended by this DPA, the Terms of Service remain in full force and effect. If any provision of this DPA is found unenforceable, the remainder remains in effect. This DPA is governed by the law and dispute-resolution provisions of the Terms of Service.

10.3 Precedence. The Annexes are incorporated into and form part of this DPA. In the event of a conflict regarding the Processing of Personal Data, the following order of precedence applies: (a) this DPA (including its Annexes); (b) the service-provider commitments in Section 8.2.1 of the Terms; and (c) the remainder of the Terms — provided that, as between this DPA and Section 8.2.1 of the Terms, whichever affords Data Subjects greater protection controls.

10.4 Notices. Notices under this DPA will be given as provided in the Terms (Section 25.5); Customer should send DPA-related notices to compliance@onerooflabs.com, and OneRoof will send Security-Incident and other DPA notices to the contact described in Section 6.1.

10.5 This DPA may be electronically accepted as part of the Terms of Service or executed by the Parties.

Annex IDetails of Processing

A. Subject matter. OneRoof's provision of the OneRoof CRM Services to Customer as described in the Terms.

B. Duration. For the term of the Customer's subscription to the Services, plus any wind-down, retention, or deletion period described in the Terms, Privacy Policy, and Section 9 of this DPA.

C. Nature and purpose. Hosting, storage, transmission, organization, retrieval, analysis, and other Processing of Personal Data as necessary to provide CRM, sales-pipeline, telephony/dialer, email and calendar, document and e-signature, proposal, prospecting/skip-tracing, roof-measurement, material-ordering, AI-assistance, mapping/canvassing, reporting, and related features the Customer chooses to use.

D. Categories of Data Subjects

  • Customer's Authorized Users (employees, agents, sales representatives, canvassers, contractors);
  • Customer's Consumers (leads, prospects, homeowners, customers, applicants, references); and
  • Property owners and other individuals identified through prospecting/skip-tracing and public records.

E. Categories of Personal Data

  • Identifiers and contact data: names, telephone numbers, email addresses, physical/mailing addresses;
  • Demographic and household data: dates of birth, approximate age, household/co-owner and pet information;
  • Employment and financial data: employer, job title, income, employment dates, screening/background and income-verification information, and bank-account links (via Plaid, where enabled);
  • Government identifiers: Social Security numbers (encrypted at rest);
  • Communications: call metadata and recordings (where enabled), email content (including incoming email via the Gmail integration), notes, messages, proposals, and contracts;
  • Property data: parcel/address, valuation, equity, mortgage, and characteristics;
  • Location data: device geolocation for canvassing and property/zone locations;
  • Media and documents: photographs, receipts, uploaded documents, roof reports, and electronic signatures;
  • Account, device, usage, and log data: credentials, IP address, device/app data, access tokens, and audit/operational logs.

F. Special/Sensitive categories. Social Security numbers, financial-account information, consumer-screening information, and precise geolocation (subject to heightened obligations as set out in the Terms and this DPA).

G. Frequency. Continuous, for the duration of the Services.

Annex IITechnical and Organizational Security Measures

OneRoof maintains the following measures (as audited; subject to change provided protection is not materially diminished):

  1. Encryption in transit — TLS for data transmitted to and from the Services.
  2. Encryption at rest (field-level, AES-256-GCM) — for designated sensitive fields, including Social Security numbers (returned masked, with access audited), stored email subjects/bodies, and stored third-party OAuth refresh tokens; managed encryption keys held as platform secrets.
  3. Credential protection — passwords stored using salted, iterated hashing (PBKDF2-SHA256); access tokens not persisted in plaintext where avoidable; refresh tokens stored as identifiers with rotation and reuse-detection that revokes compromised token chains.
  4. Access control — role-based access control with per-role permissions and data-scoping; least-privilege application database role; authentication via short-lived access tokens and rotating refresh tokens.
  5. Tenant isolation — logical multi-tenant separation enforced at the database layer through row-level security keyed to each organization, with fail-closed policies and automatic organization stamping on write.
  6. Network and application hardening — security headers (including HSTS, anti-framing, content-type protection), strict cross-origin controls, input validation, rate limiting on authentication endpoints, and SSRF protections on outbound fetches.
  7. Logging and monitoring — audit logging of security-relevant events (including authentication, authorization denials, access to sensitive records such as Social Security numbers, and Google data access), plus platform observability/operational logging.
  8. Data minimization and retention — automated purge of stored email message bodies and attachments after a defined retention window (by default, 90 days); self-service deletion tooling for Google-sourced data; retention of audit and billing records as required for security and compliance.
  9. Deletion model — deletion is effected by hard deletion with referential cascade; the platform does not retain soft-deleted records, except audit and billing records and routine backups as described in this DPA.
  10. Object storage controls — files (including call recordings, documents, photographs, and product images) are stored in access-scoped object storage and served only via short-lived, signed URLs rather than by raw storage key.
  11. Segregation of duties — separation between the least-privilege application role and elevated administrative/migration access.
  12. Sub-processor management — contractual data-protection obligations imposed on Sub-Processors (Annex III).

Annex IIIAuthorized Sub-Processors

Sub-ProcessorFunctionPersonal Data ProcessedLocation
Cloudflare, Inc.Cloud hosting, edge compute, object storage (recordings, documents, photos), image processing, database connection poolingAll categories (hosting/storage)United States
Amazon Web Services (managed database hosting)PostgreSQL database hostingAll categories (storage)United States
Telnyx LLCTelephony — outbound/inbound calling, phone-number provisioning, call recordingTelephone numbers, caller IDs, call audio/metadataUnited States
Anthropic, PBCAI processing (Claude) — document review, roof-report parsing, call analysis, workflow automationDocument/image content, transcripts, and related content submitted to AI featuresUnited States
Google LLCGmail (send and read), Google Calendar, Google Maps/geocoding, and Gemini AI assistanceEmail content/metadata, calendar events, addresses, and content submitted to the assistantUnited States
Twilio Inc. (SendGrid)Transactional email deliveryRecipient email addresses, message content, attachmentsUnited States
Property & owner data providerProperty and owner data, skip-tracing, compsSearch criteria; returns owner names, phones, emails, property dataUnited States
EagleView Technologies, Inc.Aerial roof-measurement reportsProperty addresses, order/reference dataUnited States
American Builders & Contractors Supply Co. (ABC Supply)Building-materials catalog, pricing, and orderingAccount/branch identifiers, order dataUnited States
Stripe, Inc.Payment processing and billing (including Stripe Billing)Billing contact and payment-method dataUnited States
OneRoof billing/onboarding portal (OneRoof-operated)Billing-session brokering and onboardingOrganization ID, user email and nameUnited States
Plaid Inc. (where enabled)Financial-account linkingBank-account connection dataUnited States
OneRoof DocumentAI service (OneRoof-operated)Document rendering, structured editing, and electronic signatureProposal/document content, signer names and emailsUnited States

Customer will be notified of changes to this list in accordance with Section 5.3. The authoritative, current list is maintained at onerooflabs.com/subprocessors.

Signature block (if executed as a standalone document):

ONEROOF LABS LLC
By: ______________________  Name: ______________  Title: ______________  Date: __________

CUSTOMER
By: ______________________  Name: ______________  Title: ______________  Date: __________

The all-in-one roofing CRM — dialer, canvassing, measurements, payouts and mobile, with transparent pay-for-what-you-use pricing.

Pre-launch · capability preview. Prices resolve from a versioned rate card.

Platform

Dashboard & JobsAutomations & ChatPayouts & SubsMobile app

Company

Why OneRoofPricingRequest infoTrust & Security

Legal

Terms of ServicePrivacy PolicyData Processing AddendumOAuth & data use
© 2026 OneRoof Labs LLC. All rights reserved.Colorado Springs, CO